Compatibility Quick Reference for SPL2 statistical functions

An SPL2 profile maps to a set of SPL2 commands and functions that are used by a given product. See SPL2 compatibility profiles.

The following table shows which SPL2 statistical functions are supported for the Edge Processor on Enterprise.

Supported functions and syntax Description
count(value) Returns the number of occurrences in a field.
max(value) Returns the maximum value in a field.
min(value) Returns the minimum value in a field.
span(time,span-length) Groups search results by the time span you specify.
sum(value) Returns the sum of the values in a field.